For many years, insurance governance has asked whether the outputs of an AI system are reliable, explainable, and auditable. Those issues will continue to be relevant. But agentic AI opens a more fundamental question: Who gave the system the authority to act?
A preview layer can prevent an AI-generated output of questionable quality from reaching a customer. A reconstruction record can reflect on how something happened after the fact. On its own, neither of those controls can demonstrate whether an AI agent had proper authority to take specific action.
This raises an important distinction, as insurance companies begin to move toward systems that don’t merely summarize documents or recommend next steps to agents, but systems that can extract documents, direct cases, initiate workflows, create communications, or call out to other systems. The ability to perform an action at a technical level does not translate automatically into the ability to perform that action at an organizational level.
The governance question changes when AI can act
Regarding the claim, an AI agent may be expected, depending on the context, to research policies, compare documents presented, and provide a recommendation to send the claim to an additional reviewer. It is different for the AI agent to approve a change of claim status or pay the claim, understand and change the reserve, or send any communication to the customer that has a potential effect.
It may be technically possible to perform all those actions via connected devices. It should not be equally permissible to do all those actions.
That gap, however, in my opinion, needs an authority layer to be produced by insurers: an authoritative policy and enforcement layer between what the agent can do and what the enterprise allows it to do for a specific context.
The world of bureaucracy harbors an authority layer—and this layer must answer the following five questions, in practical terms, before some action is to be executed: Who is this agent? On whose behalf is it acting? What specific action is it entitled to execute? Under what conditions is it entitled to execute the action? When shall its authority cease or get annulled?
Capability is not authority
Access is often the first control for a given application security area: can this service access that database or call that API? Instead of focusing on access to spaces, agentic systems require a tighter granularity for the access question: should this agent be permitted to take this action, on this customer, in this workflow, and at this time?
But this goes well beyond authentication. An authenticated principal could still be subject to over-authorization.
In 2026, NIST began to make this distinction explicit. As part of its AI Agent Standards Initiative, it lists agent authentication and identity infrastructure as a research priority enabling secure human-agent and multi-agent interactions. Meanwhile, a separate project at the NIST National Cybersecurity Center of Excellence looks at standards-based means to identify agents and authorize what they are permitted to access and do as organizations evolve from generative content production to generative autonomous decision-making and action.
The practical implication for insurers is clear-cut. Agent authorizations should adhere to the business need rather than being an entitlement derived from the application or employee account that linked the agent to a resource.
If an agent assisting a service representative can create and edit work items within a policy, as well as generate a response, that should not automatically allow for the entirety of changes the service representative is able to make to the beneficiary of the policy, remove coverage, or issue disbursements.
Build an authority envelope around each agent
The most effective operational definition requires establishing an authority envelope for each production agent.
The envelope should identify the nature of the agent; the person, role, or workflow for which it is acting; the systems and data to which it has access; the actions it is allowed to take; any limits on transactions or value; any conditions that require human consent; whether it can pass authority to another agent; and a time or event after which its authority ceases.
Meanwhile, three levels are to be designed that are usually confused as a singularity:
- Recommendation: The agent proposes an action.
- Decision: The workflow determines what should happen.
- Execution: A system of record is changed, money moves, coverage is affected or a customer is contacted.
A given insurer can have extensive automation at the appropriate recommendation and slightly more robust control at the decision and execution nodes. More robust control should follow the action and not be related to the complexity of the model.
This suggestion aligns with the increasing attention given by insurance regulators to the agentic risk. The documents presented at the NAIC's August 2026 Big Data and Artificial Intelligence Working Group meeting identified the agentic AI failure pattern as "Unauthorized or poorly bounded agentic behavior affecting coverage, claims, or service." The documents also say that defined action boundaries, override authority, tested kill switches, rollback, and full action logging are all signs the insurer's controls are effective in practice.
Multi-agent systems create a second authority problem
The issue becomes harder when one agent can call another.
Agent-to-agent interoperability is developing rapidly. By April 2026, the A2A protocol was formally supported by more than 150 organizations, as reported by the Linux Foundation. It was in production across financial services, insurance, and many other industries. The objective of these protocols is to enable agents to discover, communicate, and coordinate with one another across tools, vendors, and environments.
Overlapping. Therein lies value, too; however, the greater concern of governance is for the insurance industry to accomplish before multi-agent systems are able to mature – does the permission travel with necessity?
It should not.
The mere ability to communicate between agents should not result in transitive authority. For example, if agent A has permission to read a claim and requests that agent B perform a specialized action on their behalf, agent B should not be able to inherit the entirety of agent A's permissions, and agent A should not gain the transitive permissions from agent B through that delegation.
Handoffs must also be evaluated against the business purpose for which they were created, the identity of the party requesting the handoff, the action authorized by the handoff, and the risks associated with the transaction. In other words, an agent should not be able to do indirectly what it is not able to do directly.
Human oversight needs an authority trigger
“Human in the loop” is still valuable jargon, but more clarity is necessary for agentic systems. Human review should be contextually relevant, based on constraints of powers, rather than an arbitrary addition into all workflows.
An action may require a qualified tool if it can change a legal or financial situation, it is above a certain threshold, it represents an exception, it uses a new tool, it crosses a domain boundary, or it is outside normal operations for this agent.
Routine behavior can be kept automatic, provided that the conditions for automaticity are met. The intention is not to ‘put a human on the loop’ in front of every agent’s action. The intention is to make human authority exist precisely in those instances where the organization’s authority should not be delegated to software.
Finally, authority should be easily revocable by the insurer. Organizations may need to revoke a model even when it is predicting accurately and the agent is doing what it's been trained to do. Changes in data sources, downstream systems that did not operate as expected, vendor upgrades which modified workflows, or simply the appearance of a new risk that was not considered before are all scenarios where revocation may be necessary. Containment and revocation are therefore part of the authority design and not exclusively of the incident response design.
Six questions insurance leaders should ask now
Before allowing an AI agent to execute production actions, insurance leaders should be able to answer six questions:
- Can we identify the agent and the business principal on whose behalf it is acting?
- Can we distinguish what the agent may read, recommend, decide, and execute?
- Do high-impact actions have explicit limits or approval requirements?
- Does delegated work preserve the original authority boundary rather than silently expanding it?
- Can we revoke an agent's authority quickly without disabling the entire business process?
- Can we prove which authority rule permitted or blocked a consequential action?
If those answers are unclear, the organization may have agent access, but it does not yet have agent governance.
From controlled AI to authorized AI
The third step of AI governance in the insurance industry is not a more improved model or more descriptive logs; instead, it should be control over agency in black and white.
In other words, the insurer wants to know whether the AI was correct, whether the decision-making process is traceable, and whether a human being took part in it somewhere, and additionally, whether the AI was enabled to act, within a specified remit, on behalf of a particular identifiable business party.
What distinguishes an AI agent from an AI system is whether there is the authorization to act.
Similarly, it is essential to ensure that AI interventions are endowed with appropriate authority as they become more prevalent in claims, underwriting, policy servicing, and customer operations. Allow every agent to have an identity; bestow only the authority necessary to accomplish its function; make delegation explicit (but not entirely transparent); require authorization for any increase in consequences; create temporary permissions where appropriate; and immediately revoke where possible.
Agentic AI can provide much more that will result in better insurance governance. The insurance governance will provide the organization with the ability to show as clearly as possible where that ends.
